Bank-Impersonation Wire Transfer Request: Which Attack Is It?

Answer Correct answer: A — The urgent wire-transfer instruction sent from the company's bank domain to accounting is a business email compromise (BEC) fraud attempt.

A company's accounting department receives an urgent payment message from the company's bank domain with instructions to wire transfer funds. The sender requests that the transfer be completed as soon as possible. Which of the following attacks is described?

  1. Business email compromise Correct Answer
  2. Vishing
  3. Spear phishing
  4. Impersonation

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you can separate the named fraud campaign (BEC) from the generic technique labels, and the trap is picking 'Impersonation' or 'Spear phishing' because both accurately describe part of what the attacker did.

An urgent wire-transfer instruction that appears to come from the company's own bank is a business email compromise (BEC) — a finance-targeted social-engineering fraud, not generic vishing or spear phishing. This page confirms why option A is the SY0-701 answer and why impersonation is only the mechanism behind it.

Selecting D. Impersonation because the sender spoofs the bank's domain, or C. Spear phishing because the message is targeted; both describe the mechanism or delivery channel, while the scenario's bank-plus-accounting-plus-wire-transfer objective matches CompTIA's definition of business email compromise.

Community Discussion (4 comments)

Anyio 👍 3 Selected: A
The correct answer is: A. Business Email Compromise (BEC) Explanation: Business Email Compromise (BEC) is a targeted attack where attackers impersonate a trusted entity (e.g., a bank or executive) to trick victims into performing financial transactions or revealing sensitive information. In this scenario, the attacker sent an urgent payment request appearing to come from the bank, which is a hallmark of BEC. Other Options: B. Vishing: Involves voice-based phishing attacks over the phone, which is not relevant here as the communication was via email. C. Spear Phishing: Although this attack is also targeted, spear phishing typically involves obtaining sensitive information like credentials, not direct wire transfer requests. D. Impersonation: While impersonation is a tactic used in BEC, it’s not the specific attack type described in this scenario.
jbmac 👍 1 Selected: A
The correct answer is: A. Business email compromise Explanation: Business Email Compromise (BEC) is a type of social engineering attack where an attacker impersonates a high-level executive, a trusted vendor, or another party within the organization to trick employees into transferring money or sensitive information. In this case, the attack involves the accounting department receiving an urgent payment message, which is a hallmark of BEC. The attackers typically use social engineering tactics to create a sense of urgency and deceive the victim into transferring funds.
iliecomptia 👍 4 Selected: A
From CompTIA study guide: BEC= An impersonation attack in which the attacker gains control of an employee’s account and uses it to convince other employees to perform fraudulent actions. Pretty much describes what is going on here.
jennyka76 👍 1 Selected: C
Examples of spear phishing attacks include: CEO fraud, where a threat actor impersonates a CEO to trick employees into transferring money Invoice fraud Bank transfer fraud Employee fraud

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario stacks the three hallmarks CompTIA attaches to business email compromise: a trusted external identity (the company's bank domain), a finance function as the target (accounting), and manufactured urgency pushing an outbound wire transfer. As iliecomptia points out, the study guide describes BEC as "BEC= An impersonation attack in which the attacker gains control" — the fraud is the purpose of the attack, not the phishing mechanics that deliver it. Anyio reaches the same conclusion, noting that in BEC "attackers impersonate a trusted entity (e.g., a bank or executive)" to trick victims into performing a financial transaction. Because the requested action is an irrevocable money movement to an attacker-controlled account, SY0-701 labels this BEC (also called email account compromise) rather than a generic phishing category. The learner vote record is unanimous on A, which matches the exam blueprint's treatment of this exact fraud pattern.

Why the Other Options Are Wrong

B. Vishing requires a voice channel — a phone call, voicemail, or VoIP lure — and nothing in the scenario describes spoken contact; the lure arrives as a written payment message. C. Spear phishing describes targeted credential harvesting or malware delivery against a specific group, which is the delivery technique rather than the wire-fraud objective; jennyka76 lists CEO fraud and bank transfer fraud as spear-phishing examples, but the exam blueprint files bank-transfer fraud squarely under BEC. D. Impersonation is genuinely present — an attacker is posing as the bank — but it is the umbrella term covering helpdesk calls, badge cloning, and vendor spoofing alike, so it is the second-best answer rather than the best one. jbmac's observation that a BEC attacker "impersonates a high-level executive, a trusted vendor" shows how the impersonation label gets absorbed once a more specific named attack fits.

Community Comment Notes

The community is effectively unanimous here, with 89 votes on A and no dissent beyond one learner choosing C. iliecomptia anchors the answer in the official study guide wording rather than intuition, which is exactly how this question should be reasoned. Anyio breaks the definition into its parts — impersonated trusted entity plus a financial transaction — and jbmac adds the insider detail of targeting the accounting department. jennyka76's vote for spear phishing is a useful reminder that the categories overlap, but that overlap is precisely why the exam expects the most specific named attack that matches the outcome.

Official Reference

Exam Strategy

When one option names a specific fraud campaign (BEC) and another names only the underlying technique (impersonation, spear phishing), choose the specific campaign that matches the requested action and victim group. Anchor your decision on the money movement and the finance-department target, not on the fact that the sender address was spoofed. Reading for keywords like 'urgent', 'wire transfer', and 'bank domain' will point you to BEC every time on SY0-701.

Frequently Asked Questions

Why isn't impersonation (D) the best answer if the sender spoofed the bank?

Impersonation is only the mechanism; SY0-701 wants the named attack that matches the finance-fraud outcome, and BEC is the specific label for bank or executive spoofing that drives wire transfers.

How does BEC differ from spear phishing in this bank wire scenario?

Spear phishing is the delivery method aimed at specific users, while BEC is the goal-oriented fraud — convincing accounting to send funds to an attacker-controlled account.

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide